CVE-2026-4892 – dnsmasq DNS
“When DNS breaks, everything that depends on it is suddenly exposed.”
This patch addresses multiple vulnerabilities in dnsmasq that impact DNS request processing and memory handling. The issues could allow attackers to disrupt service or potentially manipulate responses under certain conditions. CVE-2026-2291 has a CVSS score of 7.3, which is High severity. CVE-2026-4890 has a CVSS score of 7.5, which is High severity. CVE-2026-4891 has a CVSS score of 5.3, which is Medium severity. CVE-2026-4892 has a CVSS score of 8.4, which is High severity. CVE-2026-4893 has a CVSS score of 5.3, which is Medium severity. CVE-2026-5172 has a CVSS score of 7.3, which is High severity.
No verified exploitation has been confirmed. However, given dnsmasq’s role in network infrastructure, these vulnerabilities increase risk across any environment relying on it for DNS resolution, particularly in routers, embedded systems, and enterprise network services.
Key Details
- Attack Vector
- Local
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None